When conducting research, it is crucial to ensure that any data gathered and subsequently used is handled correctly. Processing personal data responsibly is both an ethical obligation and a legal requirement. Ethics and data protection guidelines and laws, such as the European Union’s General Data Protection Regulation (GDPR), which governs the processing of personal data, must be adhered to.
For the ICAREWOUNDS research project, it is paramount to guarantee compliance with all relevant guidelines and regulations for all its activities. In order to achieve this, CyberEthics Lab., a partner of the project dealing with ethics, societal and regulatory concerns, proposes an ethical approach throughout the project, to be adopted by each partner of the consortium, in line with respect for the freedom and fundamental rights of individuals, as well as compliance with European Union and national data protection rules.
This blog post provides an overview of the approach chosen to draft the project’s template for a Data Processing Agreement (DPA) — an essential legal document required when the data controller (i.e., a partner of the project) shares personal data obtained from a data subject (individual external to the project) with a data processor (i.e., another partner or third party). In particular, to ensure the strictest data protection coverage, the ICAREWOUNDS adopted the EU Commission’s template to draft the project’s DPA for use by all partners, ensuring consistent protection when personal data sharing occurs.
Understanding the Data Processing Agreement
Any organisation acting as a data controller that shares personal data with a third party must have a contract or another legal act, such as a Data Processing Agreement (DPA) in place with all third parties acting as processors on their behalf, and the DPA should be concluded before any personal data processing takes place.
The key distinctions between a controller and a processor are as follows:
• Data Controller: Defined in Article 4(7) of the GDPR, a data controller is “the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law” [1].
• Data Processor: According to Article 4(8) of the GDPR, a data processor means “a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller” [1]. Typically, a data processor is another organisation that the data controller uses to help store, analyse, or communicate personal information.
A DPA is a legally binding contract that must address the specific needs, legal requirements, and risks of individual data controller and processor relationships. Therefore, DPAs can vary in content depending on the specific context and requirements of each data processing arrangement. However, Article 28 of the GDPR provides certain details that must be included in every agreement, such as the subject matter and duration of the processing, the nature and purpose of the processing, the type of personal data and categories of data subjects, and the obligations and rights of the controller, among other responsibilities.
ICAREWOUNDS’ DPA Based on the EU SCCs
On June 4, 2021, the European Commission published its new set of Standard Contractual Clauses (SCCs). These SCCs are templates that organisations can use to comply with the GDPR rules on outsourced data processing. Specifically:
• The first template is for SCCs between controllers and processors in the EU/ European Economic Area (EEA) [2].
• The second template is for module-based SCCs as a tool for international transfers, i.e. to comply with the requirements of the GDPR for transferring personal data to countries outside of the EEA [3].
While organisations are free to adopt their version of DPAs, the ICAREWOUNDS decided to adopt the EU Commission’s official, standardised, and pre-approved template which provides a coherent approach for the relationship between controllers and processors throughout the EEA to ensure compliance with Article 28(3) and (4) of the GDPR. The DPA template, based on the EU SCCs, was distributed to all partners in the third month of the project (July). Partners are expected to adapt and integrate this template (according to their specific needs) and it must be approved by partners’ legal departments/DPOs before it can be deployed.
To ensure legal certainty provided by an EU act, the EU SCCs in the ICAREWOUNDS DPA template cannot be modified, except in the following cases:
• To select specific options offered in the text.
• To complete the text where necessary (indicated by square brackets).
• To fill in the Annexes. These adaptations are not considered as altering the core text.
Additionally, partners can add extra clauses, or the EU SCCs themselves can be part of a larger agreement. In the event of a conflict between the EU clauses provided in the project’s DPA template and additional clauses, the EU SCCs will prevail.
What Are the Advantages of Using SCCs for the Project?
As was already mentioned before, although companies can freely choose whether or not to use the EU SCCs for their DPAs, these clauses are increasingly recognised as the “gold standard” of data protection across the EU. SCCs, which are adopted by the Commission under Article 28(7) of the GDPR, can be relied upon throughout the entire EEA and are binding on all EEA data protection authorities. Their validity can be contested only before the Court of Justice of the European Union.
Conclusions
In conclusion, the ICAREWOUNDS project has adopted the EU Commission’s Standard Contractual Clauses (SCCs) for the Data Processing Agreement (DPA) to ensure a high level of personal data protection. By using the EU SCCs, ICAREWOUNDS not only aims to align with GDPR but also emphasises the strong commitment to protecting personal data throughout the project.
Souces:
1. European Parliament and Council, General Data Protection Regulation 2016/679, 2016. [Online]. Available at: https://eur-lex.europa.eu/eli/reg/2016/679/oj
2. European Commission, Standard contractual clauses for controllers and processors in the EU/EEA, 2021. [Online]. Available at: https://commission.europa.eu/publications/standard-contractual-clauses-controllers-and-processors-eueea_en
3. European Commission, Standard contractual clauses for international transfers, 2021. [Online]. Available at: https://commission.europa.eu/publications/standard-contractual-clauses-international-transfers_en

ICAREWOUNDS project has received funding from the European Commission, ISCIII, NCBR, HRB, AKA and MUR under the framework the co-fund partnership of Transforming Health and Care Systems, THCS, (GA N° 101095654 of the EU Horizon Europe Research and Innovation Programme).